NetBSD/pkgsrc msY9WIddoc CHANGES-pkgsrc-2026Q1

   note #7074
VersionDeltaFile
1.1.2.9+6-1doc/CHANGES-pkgsrc-2026Q1
+6-11 files

NetBSD/pkgsrc FTTeGhuwww/firefox140 distinfo Makefile, www/firefox140-l10n distinfo Makefile

   Pullup ticket #7074 - requested by gutteridge
   www/firefox140: security fix
   www/firefox140-l10n: dependent update

   Revisions pulled up:
   - www/firefox140-l10n/Makefile                                  1.8
   - www/firefox140-l10n/distinfo                                  1.8
   - www/firefox140/Makefile                                       1.13
   - www/firefox140/distinfo                                       1.12

   ---
      Module Name:    pkgsrc
      Committed By:   gutteridge
      Date:           Thu Apr  9 18:37:06 UTC 2026

      Modified Files:
              pkgsrc/www/firefox140: Makefile distinfo

      Log Message:

    [80 lines not shown]
VersionDeltaFile
1.7.2.1+307-307www/firefox140-l10n/distinfo
1.11.2.1+4-4www/firefox140/distinfo
1.7.2.1+2-2www/firefox140-l10n/Makefile
1.12.2.1+2-2www/firefox140/Makefile
+315-3154 files

NetBSD/pkgsrc kKIfqU8editors/reovim distinfo, editors/reovim/patches patch-server_lib_drivers_module-loader_src_discovery.rs

   editors/reovim: fix patchsum

   While here, allow building on SmartOS.
VersionDeltaFile
1.2+11-23editors/reovim/patches/patch-server_lib_drivers_module-loader_src_discovery.rs
1.5+2-2editors/reovim/distinfo
+13-252 files

NetBSD/pkgsrc n6ni9kWdoc CHANGES-2026

   Note update of net/exabgp to 5.0.8.
VersionDeltaFile
1.2206+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc SSj0FTinet/exabgp PLIST Makefile, net/exabgp/patches patch-lib_exabgp_application_healthcheck.py

   net/exabgp: update to version 5.0.8.

   Pkgsrc changes:
    * Remove now-integrated patch.
    * Update PLIST.
    * Checksum updates.

   Upstream changes:

   Version 5.0.8:
    * Fix: handle OPEN message with zero capabilities without crashing
      Capabilities.unpack() read the parameter type byte before checking
      whether the Optional Parameters Length was zero, raising IndexError
      when a peer sent an OPEN with no optional parameters at all (a valid
      single 0x00 byte payload per RFC 4271). The early-return guard sat
      below the offending read so it never helped. Alternative to PR #1375.

   Version 5.0.7:
    * Fix: send zero-length capabilities in OPEN message (#1371)

    [221 lines not shown]
VersionDeltaFile
1.14+333-102net/exabgp/PLIST
1.46+8-2net/exabgp/Makefile
1.23+4-5net/exabgp/distinfo
1.4+1-1net/exabgp/patches/patch-lib_exabgp_application_healthcheck.py
+346-1104 files

NetBSD/pkgsrc XjIl0midoc CHANGES-2026

   doc: Updated www/chromium to 147.0.7727.55
VersionDeltaFile
1.2205+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc WY5RZg3www/chromium distinfo, www/chromium/patches patch-chrome_browser_about__flags.cc patch-chrome_browser_policy_configuration__policy__handler__list__factory.cc


   www/chromium: update to 147.0.7727.55

   * 147.0.7727.55
   This update includes multiple security fixes. Please see the
   Chrome Security Page for more information.
   [$43000][493319454] Critical CVE-2026-5858: Heap buffer overflow in WebML.
   Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-17
   [$43000][494158331] Critical CVE-2026-5859: Integer overflow in WebML.
   Reported by Anonymous on 2026-03-19
   [$11000][486495143] High CVE-2026-5860: Use after free in WebRTC.
   Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-22
   [$3000][486927780] High CVE-2026-5861: Use after free in V8.
   Reported by 5shain on 2026-02-23
   [TBD][470566252] High CVE-2026-5862: Inappropriate implementation in V8.
   Reported by Google on 2025-12-21
   [TBD][484527367] High CVE-2026-5863: Inappropriate implementation in V8.
   Reported by Google on 2026-02-14

    [111 lines not shown]
VersionDeltaFile
1.38+1,574-1,561www/chromium/distinfo
1.17+115-79www/chromium/patches/patch-chrome_browser_about__flags.cc
1.17+37-28www/chromium/patches/patch-chrome_browser_policy_configuration__policy__handler__list__factory.cc
1.17+48-8www/chromium/patches/patch-net_socket_udp__socket__posix.cc
1.16+40-13www/chromium/patches/patch-components_signin_public_base_signin__switches.cc
1.17+29-20www/chromium/patches/patch-chrome_browser_profiles_chrome__browser__main__extra__parts__profiles.cc
+1,843-1,7091,568 files not shown
+4,854-4,2961,574 files

NetBSD/pkgsrc tGBhlcqdoc TODO CHANGES-2026

   doc: Updated www/esbuild to 0.28.0
VersionDeltaFile
1.27079+1-2doc/TODO
1.2204+2-1doc/CHANGES-2026
+3-32 files

NetBSD/pkgsrc e6ozkpmwww/esbuild distinfo Makefile

   www/esbuild: update to 0.28.0

   * 0.28.0
   - Add support for with { type: 'text' } imports (#4435)
   - Add integrity checks to fallback download path (#4343)
   - Update the Go compiler from 1.25.7 to 1.26.1

   * 0.27.7
   - Fix lowering of define semantics for TypeScript parameter properties (#4421)
VersionDeltaFile
1.9+4-4www/esbuild/distinfo
1.32+2-3www/esbuild/Makefile
1.7+0-0www/esbuild/go-modules.mk
+6-73 files

NetBSD/pkgsrc-wip 32f242echromium distinfo COMMIT_MSG, chromium/patches patch-chrome_browser_about__flags.cc patch-chrome_browser_policy_configuration__policy__handler__list__factory.cc

chromium: update to 147.0.7727.55
DeltaFile
+1,574-1,561chromium/distinfo
+115-79chromium/patches/patch-chrome_browser_about__flags.cc
+122-43chromium/COMMIT_MSG
+37-28chromium/patches/patch-chrome_browser_policy_configuration__policy__handler__list__factory.cc
+48-8chromium/patches/patch-net_socket_udp__socket__posix.cc
+40-13chromium/patches/patch-components_signin_public_base_signin__switches.cc
+1,936-1,7321,567 files not shown
+4,986-4,4021,573 files

NetBSD/pkgsrc nY0V1ISdevel/nasm Makefile

   ensure GNU sed is used to avoid incompatibilities with other sed implementations
VersionDeltaFile
1.73+2-2devel/nasm/Makefile
+2-21 files

NetBSD/pkgsrc-wip 86b0664libreswan PLIST Makefile, libreswan-4 Makefile PLIST

libreswan: delete libreswan-4, rename libreswan-5 back to libreswan

Upstream no longer support v4.x; v5.x considered stable.
DeltaFile
+0-103libreswan-5/PLIST
+103-0libreswan/PLIST
+0-82libreswan-5/Makefile
+82-0libreswan/Makefile
+0-79libreswan-4/Makefile
+0-72libreswan-4/PLIST
+185-33612 files not shown
+243-44918 files

NetBSD/pkgsrc fIHZhvcdoc TODO

   doc/TODO: rspamd update

   + rspamd-4.0.1.
VersionDeltaFile
1.27078+2-2doc/TODO
+2-21 files

NetBSD/pkgsrc Z9qYQX3doc CHANGES-2026

   doc: Updated lang/php84 to 8.4.20
VersionDeltaFile
1.2203+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc eXN4qnulang/php phpversion.mk, lang/php84 distinfo

   lang/php84: update to 8.4.20

   PHP 8.4.20 (2026-04-09)

   - Bz2:
     . Fix truncation of total output size causing erroneous errors. (ndossche)

   - Core:
     . Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in
       get_property_ptr_ptr for lazy proxies). (iliaal)

   - DOM:
     . Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and
       xml:lang attributes). (ndossche)

   - FFI:
     . Fixed resource leak in FFI::cdef() onsymbol resolution failure.
       (David Carlier)


    [50 lines not shown]
VersionDeltaFile
1.20+4-4lang/php84/distinfo
1.496+2-2lang/php/phpversion.mk
+6-62 files

NetBSD/src TikjSb9distrib/sparc64/xminiroot Makefile

   bump
VersionDeltaFile
1.38+2-2distrib/sparc64/xminiroot/Makefile
+2-21 files

NetBSD/pkgsrc 8XjEhWF. .cvsignore

   add toplevel .cvsignore file to ignore wip/ subdirectory
VersionDeltaFile
1.1+1-0.cvsignore
+1-01 files

NetBSD/pkgsrc NRQUnvqx11/kitty distinfo, x11/kitty/patches patch-setup.py

   kitty: Fix serious bug in the setup.py patch.

   Ensure candidates is a tuple, not a string.  That single missing comma caused
   builds on macOS to traverse the entire file system multiple times as:

     for candidate in ('@PREFIX@/share/fonts/')

   expands to e.g. ['/', 'o', 'p', 't', '/', ...], whereas:

     for candidate in ('@PREFIX@/share/fonts/',)

   correctly expands to e.g. ['/opt/pkg/share/fonts'].
VersionDeltaFile
1.5+3-3x11/kitty/patches/patch-setup.py
1.41+2-2x11/kitty/distinfo
+5-52 files

NetBSD/pkgsrc uiMcNchparallel/hwloc Makefile

   hwloc: ignore shell portability problems in bash completion script
VersionDeltaFile
1.44+4-1parallel/hwloc/Makefile
+4-11 files

NetBSD/src BJimcUJsys/dev/ata ata.c

   Avoid crash due to ATABUSIODETACH and ATABUSIOSCAN ioctls.

   Addresses PR kern/60158
VersionDeltaFile
1.172+12-7sys/dev/ata/ata.c
+12-71 files

NetBSD/pkgsrc uo5W2Iddoc TODO

   doc/TODO: + calibre-9.7.
VersionDeltaFile
1.27077+2-2doc/TODO
+2-21 files

NetBSD/pkgsrc eaypNdjdoc CHANGES-2026

   doc: Updated net/ruby-addressable to 2.9.0
VersionDeltaFile
1.2202+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc VGw3dPKnet/ruby-addressable distinfo Makefile

   ruby-addressable: update to 2.9.0

   Upstream changes:
    https://github.com/sporkmonger/addressable/blob/addressable-2.9.0/CHANGELOG.md

   Addressable 2.9.0

     * fixes ReDoS vulnerability in Addressable::Template#match
       (fixes incomplete remediation in 2.8.10)

   Addressable 2.8.10

     * fixes ReDoS vulnerability in Addressable::Template#match
VersionDeltaFile
1.31+4-4net/ruby-addressable/distinfo
1.30+2-2net/ruby-addressable/Makefile
+6-62 files

NetBSD/src xokUososys/dev/ic wdc.c

   Avoid crash due to `atactl atabusX reset` when no drives are attached
VersionDeltaFile
1.314+6-5sys/dev/ic/wdc.c
+6-51 files

NetBSD/pkgsrc-wip e25ed34libvips distinfo PLIST

Bump libvips to 8.18.2
DeltaFile
+3-3libvips/distinfo
+2-2libvips/PLIST
+1-1libvips/Makefile
+6-63 files

NetBSD/pkgsrc KHN8t19doc CHANGES-2026

   doc: Updated ruby-gnome packages to 4.3.6
VersionDeltaFile
1.2201+18-1doc/CHANGES-2026
+18-11 files

NetBSD/pkgsrc AdP3ykqdoc CHANGES-2026

   Updated devel/lazygit, devel/catch2, net/iperf3
VersionDeltaFile
1.2200+4-1doc/CHANGES-2026
+4-11 files

NetBSD/pkgsrc Lxypb1Bnet/iperf3 distinfo Makefile

   iperf3: updated to 3.21

   iperf-3.21 includes support for GSO and GRO under Linux, improves feature
   parity for macOS, and adds a number of minor bugs and enhancements. More
   details on the changes can be found in the release notes.
VersionDeltaFile
1.26+4-4net/iperf3/distinfo
1.27+2-2net/iperf3/Makefile
+6-62 files

NetBSD/pkgsrc eueJeN1devel/catch2 distinfo Makefile

   catch2: updated to 3.14.0

   3.14.0

   Fixes

   Added missing <cstdint> includes.
   Fixed suppression of empty variadic macro arguments warning on Clang <19.
   Fixed catch_discover_tests failing during PRE_TEST discovery if a target does not have discoverable tests.
   Fixed build of the main library failing with CATCH_CONFIG_PREFIX_ALL defined.
   JUnit reporter outputs single failed (errored/skipped) assertion per test case.

   Improvements

   The default implementation of --list-tags and --list-listeners has a quiet variant.
   Suppressed the new Clang warning about __COUNTER__ usage.
   Line-wrapping counts utf-8 codepoints instead of bytes.
   Combining character sequences are still miscounted, but Catch2 does not aim to fully support Unicode.
VersionDeltaFile
1.28+4-4devel/catch2/distinfo
1.27+2-2devel/catch2/Makefile
+6-62 files

NetBSD/pkgsrc DwzwYKDdevel/lazygit distinfo go-modules.mk

   lazygit: updated to 0.61.0

   0.61.0

   Features

   Show pull requests against branches

   Enhancements

   Add support for clicking on arrows in the file list to expand/collapse directories
   Remove empty directories after discarding untracked files
   Make file sort order and case sensitivity configurable, and default to mix files and folders
   Allow customizing the window width/height thresholds for when to use portrait mode
   Log hashes of local branches when deleting them
   Add condition field to custom command prompts

   Fixes


    [6 lines not shown]
VersionDeltaFile
1.21+178-1,477devel/lazygit/distinfo
1.17+58-491devel/lazygit/go-modules.mk
1.71+2-3devel/lazygit/Makefile
+238-1,9713 files